Jenkins Credentials Binding Plugin是Jenkins开源的一个将存储在Jenkins中的安全凭据绑定到构建过程的环境变量中的插件。 Jenkins Credentials Binding Plugin 719.v80e905ef14eb_及之前版本存在路径遍历漏洞,该漏洞源于未清理文件和zip文件凭据的文件名,可能导致能够向作业提供凭据的攻击者将文件写入节点文件系统上的任意位置,如果Jenkins配置允许低权限用户为在内置节点上运行的作业配置文件或zip文件凭据,可能导致远
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Jenkins Project | Jenkins Credentials Binding Plugin | ≤ 719.v80e905ef14eb_ |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Jenkins Project | Jenkins Credentials Binding Plugin | 0 ~ 719.v80e905ef14eb_ | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42525 | Jenkins Microsoft Entra ID Plugin 输入验证错误漏洞 | |
| CVE-2026-42524 | Jenkins HTML Publisher Plugin 跨站脚本漏洞 | |
| CVE-2026-42523 | Jenkins GitHub Plugin 跨站脚本漏洞 | |
| CVE-2026-42521 | Jenkins Matrix Authorization Strategy Plugin 代码问题漏洞 | |
| CVE-2026-42522 | Jenkins GitHub Branch Source Plugin 安全漏洞 | |
| CVE-2026-42519 | Jenkins Script Security Plugin 安全漏洞 |
No comments yet